PT-2026-90728 · Webassembly+3 · Wabt
CVE-2026-90648
·
Published
2026-09-12
·
Updated
2026-09-22
CVSS v4.0
7.1
High
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
WebAssembly wabt versions prior to 1.0.42
Description
An issue in wasm2c allows a sandbox escape, primarily on 32-bit platforms, through a method known as a table flip attack. The
wasm rt allocate funcref table() function in wasm2c/wasm-rt-impl-tableops.inc fails to check the return value of calloc(). If the funcref table allocation fails, table->data remains NULL while table->size retains the guest-declared element count. Consequently, bounds checks are bypassed, and table element accesses resolve to absolute memory addresses. This enables arbitrary read and write access to host process memory and arbitrary code execution via table.get, table.set, and call indirect, compromising the isolation provided by wasm2c. This affects applications using wasm2c as a sandboxing boundary, such as RLBox and WasmBoxC, including Firefox's implementation for Graphite, Hunspell, Ogg, Expat, and Woff2 libraries. Exploitation typically requires allocation failure due to memory pressure, 32-bit host limitations, address-space limits (RLIMIT AS), or specific kernel settings like vm.overcommit memory=2.Recommendations
Update WebAssembly wabt to version 1.0.42 or later.
Exploit
Fix
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wabt